Privacy Policy

Purpose

Your privacy is important to us, and so is being transparent about the ways in which we collect, use and share information about you. This policy is intended to help you understand:

  • What information we collect about you
  • How we use information we collect
  • How we share information we collect
  • How we store and secure information we collect
  • How to access and control your information
  • How we transfer information we collect internationally
  • Other important security information

Standard of Practice

This Privacy Policy covers the information we collect about you when you use our products or services, or otherwise interact with us (for example, by attending our events, contacting us). Sprigg, we and us refers to SpriggHR Inc. We offer a range of products, including a comprehensive cloud-based performance management solution suite. We refer to these products, together with our other services and websites as “ Products & Services” in this policy.

This policy also explains your choices about how we use information about you. Your choices include how you can object certain uses of information about you and how you can access and update certain information about you. If you do not agree with this policy, do not access or use our Products & Services or interact with any aspect of our business.

Where we provide the Products & Services under contract with an organization (for example, your company that you are employed by), that organization controls the information processed by the Products & Services. For more information, please see Notice to End Users below.

Procedure

What information we collect about you

We collect information about you when you provide it to us, when you use our Products & Services, and when other sources provide it to us, as further described below.

Information you provide to us

We collect information about you when you input it into the Products & Services or otherwise provide it directly to us.

Account and Profile Information: We collect information about you when you sign-up for our Products & Services, register for an account, create or modify your profile, set preferences, sign-up for or make purchases through the Products & Services. For example, you provide your contact information and in some cases, billing information when you sign-up and register for the Products & Services. You also have a display name, option of having a profile photo, job title and other details to your profile information to be displayed in our Products & Services. We keep track of your preferences when you select settings within the Products & Services.

Content you provide through our Products & Services: The Products & Services include the SpriggHR Inc. products you use, where we collect and store the content that you post, send, receive and share. This content includes any information about you that you may choose to include. Examples of content we collect and store include: performance review data, feedback messages you send and receive, files and links uploaded to the Products & Services. By using our Products & Services you are using our server, which is located in a data center. We host, store, transmit, receive or collect information about you (including your content) that is provided to us. We collect feedback you provide directly to us through the Products & Services and; we collect content using analytics techniques that hash, filter or otherwise scrub the information to exclude information that might identify you or your organization; and we collect clickstream data about how you interact with and use features in the Products & Services. Server and data center administrators can disable our collection of this information from the Products & Services via the administrator settings or prevent this information from being shared with us by blocking transmission at the local network level, for example removing a site.

Content you provide through our websites: The Products & Services also include our websites that are owned or operate by us. We collect other content that you submit to these websites, which include social media or social networking websites operated by us. For example, you provide content to us when you provide feedback, or when you participate in any interactive features, surveys, contests, promotions, activities or events.

Information you provide through our support channels: The Products & Services also include our client support, where you choose to submit information regarding a problem you are experiencing with a Product or Service. Whether you designate yourself as a technical contact, open a support ticket, speak to one of our representatives directly or otherwise engage with our support team, you will be asked to provide contact information, a summary of the problem you are experiencing, and any other documentation, screenshots or information that would be helpful in resolving the issue.

Payment information: We collect certain payment and billing information when you sign-up and register for complimentary trial and for paid Products & Services. For example, we ask you to designate a billing/accounts representative, including name and contact information, upon sign-up/registration. You might also provide payment information such as invoicing and payment method details, which we collect via secure payment processing services.

Information we collect automatically when you use the Products & Services

We collect information about you when you use our Products & Services, including browsing our websites and taking certain actions within the Products & Services.

Your use of the Products & Services: We keep track of certain information about you when you visit and interact with any of our Products & Services. This information includes the features you use; the links you click on; the type, size and filenames of attachments you upload to the Products & Services; frequently used search terms; and how you interact with others on the Products & Services. We also collect information about the teams and people you work with and how you work with them, such as who you collaborate goals with and communicate with most frequently via feedback tools. By using our server which is located in a data center, the information we collect about your use of the Products & Services is limited to clickstream data about how you interact and use features in the Products & Services, in addition to content-related information described in the “Content you provide through our Products & Services” above. Server and data center administrators can disable our collection of this information from the Products & Services via the administrator settings or prevent this information from being shared with us by blocking transmission at the local network level.

Device and Connection Information: We collect information about your computer, phone, tablet or other devices you use to access the Products & Services when you provide it to us. This device information includes your connection type and settings when you access and use our Products & Services. We also collect information through
your device about your operating system, browser type, IP address, URLs of referring/exit pages, device identifiers and crash data. How much of this information we collect depends on the type and settings of the device you use to access and use the Products & Services. Server and data center administrators can disable collection of this information via the administrator settings or prevent this information from being shared with us by blocking transmission at the local network level.

Cookies and Other Tracking Technologies: SpriggHR Inc. and our third-party partners, such as data centers, advertising, and analytics partners, use cookies and other tracking technologies (e.g. web beacons, device identifiers) to provide functionality and to recognize you across different Products & Services and devices.

Information we receive from other sources

We receive information about you from other Product & Service Users and from thirdparty services.

Other Users of the Products & Services: Other Users of our Products & Services may provide information about you when they submit content through the Products & Services. For example, you may be mentioned in a Goal Assist or Feedback message initiated by someone else. We also receive your email address from other Product & Service Users when they provide it in order to invite you to the Products & Services (such as a 360 Feedback Review). Similarly, a SpriggHR Inc. representative may provide your contact information when you provide us with information on being the designated billing/accounts contact on your organization’s account.

Other services you link to your account: We receive information about you when you or your Administrator integrate or link a third-party service with our Products & Services. For example, we receive your name, e-mail and potentially phone number as permitted by Authy’s Two-Factor Authentication settings in order to authenticate you. Your Administrator may also integrate our Products & Services with other services that you use, such as to allow you to access, store, share and edit certain content from a thirdparty through our Products & Services. For example, your Administrator may authorize our Products & Services to access, display and store files from a third-party document sharing service within the Products & Services interface. Or your Administrator may authorize our Products & Services to connect with a third-party calendaring integration so that your meetings are available through third-party services such as Microsoft Outlook and Google Calendar. The information we receive when you link or integrate our Products & Services with a third-party service depends on the settings, permission and privacy policy controlled by that third-party service. You should always check the privacy settings and notices in these third-party services to understand what data may be disclosed to us or shared with our Products & Services.

SpriggHR Inc. Partners: We work with various partners who provide consulting around our Products & Services. Some of these partners also help us to market and promote our products, services, generate leads for us, and resell our products. We receive information from these partners, such as billing information, billing contact information, organization name, what SpriggHR Inc. products you have purchased or may be interested in, evaluation information you have provided, and what events you have attended, and what country you are in.

Other Partners: We receive information about you and your activities on and off from the Products & Services from third-party partners, such as advertising and market research partners who provide us with information about your interest in and engagement with our Products & Services, and online advertisements and our websites.

How we use information we collect

How we use the information we collect depends in part on which Products & Services you use, how you use them, and any preferences you have communicated to us. Below are the specific purposes for which we use the information we collect about you.

To provide the Products & Services and personalize your experience: We use information about you to provide the Products & Services to you, including to process transactions with you, authenticate you when you login in, provide client support, and operate and maintain the Products & Services. For example, the name and photo you may provide in your account to identify you to other Product & Service Users. Our Products & Services also include tailored features that personalize your experience, enhance your productivity, and improve your ability to share information and collaborate effectively with others by analyzing the activities of your Users to provide us with activity feeds, notifications and recommendations that are most relevant for your Users. For example, we may use your activities and preferences within the Products & Services that you use and access to make recommendations that are most relevant for your organization and Users. We may also use your email domain to infer your affiliation with a particular organization or industry to personalize the content and experience you receive on our websites.

For research and development: We are also looking for ways to make our Products & Services smarter, faster, secure, integrated and useful to you. We use collective learnings about how people use our Products & Services and feedback directly provided to us to troubleshoot and to identify trends, usage, activity patterns and areas for integration and improvement of the Products & Services. In some cases, we apply these learnings across our Products & Services to improve and develop similar features or to better integrate the products and services you use. We also test and analyze new features with some Users before rolling out the feature to all Users. To communicate with you about the Products & Services: We use your contact information that has been provided to us by you to send transactional communications via email including confirming your purchases, reminding you of renewals and contract expirations, responding to your comments, questions and requests, providing client support, sending you technical notices, updates, security alerts and Administrator messages. We send you email notifications when you or others interact with you on the Products & Services, for example when you are tagged or identified in a Goal Assist, as a meeting or 360 Review participant, or when a task is assigned to you. We also send you communications as you onboard to a particular Product/Service to help you become more proficient in using that Product/Service. These communications are part of the Products & Services and in most cases you cannot opt out of them. If an opt out is available, you will find that option within the communication itself.

To market, promote and drive engagement with the Products & Services: We use your contact information and information about how you use the Products & Services to send promotional communications that may be of specific interest to you, including by email and by displaying SpriggHR Inc. ads on other organizations’ websites, as well as platforms like Google. These communications are aimed at driving engagement and maximizing what you get out of the Products & Services, including information about new features, survey requests, newsletters, and events or activities that we think may be of interest to you. We also communicate with you about new updates, products, product offers, promotions and contests. For some communications that are not a part of the Products & Services, you can control whether you receive these communications as described below under “Opt-out of communications”.

Client support: We use your information to resolve technical issues that you encounter, to respond to your requests for assistance, to analyze crash information, and to repair and improve the Products & Services.

For safety and security: We use information about you and your Products & Services use to verify accounts and activity, to monitor suspicious or fraudulent activity and to identify violations of Terms of Service policies.

To protect our legitimate business interests and legal rights: Where required by law or where we believe it is necessary to protect our legal rights, interests and the interests of others, we use information about you in connection with legal claims, compliance, regulatory, and audit functions, and disclosures in connection with the acquisition, merger or sale of a line of our business.

With your consent: We use information about you where you have given us consent to do so for a specific purpose not listed above. For example, we may publish testimonials or feature a client story to promote the Products & Services, with your permission.

Legal bases for processing (for EEA users):

If you are an individual in the European Economic Area (EEA), we collect and process information about you only where we have legal bases for doing so under applicable EU laws. The legal bases depend on the Products & Services you use and how you use them. This means we collect and use your information only where:

  • We need it to provide you the Products & Services, including to operate the Products & Services, provide client support and personalized features and to protect the safety and security of the Products & Services;
  • It satisfies a legitimate interest (which is not overridden by your data protection interests), such as for research and development, to market and promote the Products & Services and to protect our legal rights and interests;
  • You give us consent to do so for a specific purpose; or
  • We need to process your data to comply with a legal obligation.

If you have consented to our use of information about you for a specific purpose, you have the right to change your mind at any time, but this will not affect any processing that has already taken place. Where we are using your information because we or a third party (e.g. your organization) have a legitimate interest to do so, you have the right to object to that use though, in some cases, this may mean no longer using the Products & Services.

How we share information that we collect

We design Performance Management Solutions tools and suites. Our intention is to make them work well for you and your organization. This means sharing information through the Products & Services and with certain third parties. We share information we collect about you in the ways discussed below, including in connection with possible business transfers, bur we are not in the business of selling information about you to advertisers or other third parties.

Sharing with other Products & Services Users

When you use the Products & Services, we share certain information about you with other Product & Service Users.

For sharing/collaboration: You create content, which may contain information about you, and grant permission to others to see, share, edit, copy, and download that content based on settings you or your Administrator select. Some of the sharing/collaboration features of the Products & Services display some or all of your User profile information to other Product & Service Users when you share or interact with specific content. For example, when you leave Feedback or share Status Updates within the Products & Services, we display your name and potentially job title next to the comments so that other Users with access to the Products & Services understand who left the Feedback or who shared the Status Update. When you send Feedback to another User, the recipient can view any information in your public profile. Similarly, when you conduct a performance review, your name is displayed as the reviewer/individual under review.

Managed accounts and Administrators: If you sign-up/register or access the Products & Services using an email address with a domain that is owned by your employer or organization, and such organization wishes to establish an account or site, certain information about you including your name, photo, contact info, content and past use of your account may become accessible to that organization’s Administrator and other Product & Service Users sharing the same domain. If you are an Administrator for Users of a Products & Services site, we may share your contact information with current or past Product & Service Users, for the purpose of facilitating Product/Service related questions and requests.

Community Forums: Our websites offer publicly accessible blogs and issue trackers from our Development Team. You should be aware that any information provided on these websites – including profile and contact information associated with the account you use to post the information – may be read, collected, and used by any member of the public who accesses these websites. Your posts and certain profile information may remain even after your account is disabled or after your account is terminated. We urge you to consider the sensitivity of any information you input into these Products & Services. To request removal of your information from publicly accessible websites operated by us, please contact us as provided below. In some cases, we may not be able to remove your information, in which case we will let you know if we are unable to and why.

Sharing with third parties

We share information with third parties that help us to operate, provide, improve, integrate, customize, support and market our Products & Services.

Service Providers: We work with third-party service providers to provide website and application development, hosting, maintenance, backup, storage, virtual infrastructure, payment processing, analysis and other services for us, which may require them to access or use information about you. If a service provider needs to access information about you to perform services on our behalf, they do so under close instruction from us, including policies and procedures designed to protect your information.

SpriggHR Inc. Partners: We work with third parties who provide consulting, sales, and technical services to deliver and implement client solutions around the Products & Services. We may share your information with these third parties in connection with their services, such as to assist with billing and collections, to provide localized support, and to provide customizations. We may also share information with these third parties where you have provided consent to that sharing.

Third Party Apps: You, your Administrator, or other Product & Service Users may choose to add new functionality or change the behaviour of the Products & Services by integrating APIs within the Products & Services. Doing so may give third-party apps access to your account information about you such as your name, email address, photo and any content you choose in connection with those apps. If you are a billing/account contact listed on the account, we may share your details with the third-party app provider. Third-party app policies and procedures are not controlled by us, and this privacy policy does not cover how third-party apps use your information. We encourage you to review the privacy policies of third parties before connecting to or using their applications or services to learn more about their privacy and information handling practices and procedures. If you object to information about you being shared with these third parties, please uninstall the app.

Links to Third Party Sites: The Services may include links that direct you to other websites or services whose privacy practices may differ from ours. If you submit information to any of those third party sites, your information is governed by their privacy policies, not this one. We encourage you to carefully read the privacy policy of any website you visit.

Social Media Widgets: The Products & Services may include links that direct you to other websites or services whose privacy practices may differ from ours. Your use of and any information you submit to any of those third-party sites is governed by their privacy policies, not this one.
10

Third-Party Widgets: Some of our Products & Services contain widgets and social media features, such as the Twitter “tweet” button, or Slack icon. These widgets and features collect your IP address, which page you are visiting on the Products & Services, and may set a cookie to enable the feature to function properly. Widgets and social media features are either hosted by a third party or hosted directly on our Products & Services. Your interactions with these features are governed by the privacy policy of the company providing it.

With your consent: We share information about you with third parties when you give us consent to do so. For example, we often display client testimonials of satisfied customers on our public websites. With your consent, we may post your name, job title and organization alongside the testimonial.

Compliance with Enforcement Requests and Applicable Laws; Enforcement of Our Rights: In exceptional circumstances, we may share information about you with a third party if we believe that sharing is reasonably necessary to (a) comply with any applicable law, regulation, legal process or governmental request, including to meet national security requirements, (b) enforce our agreements, policies and terms of service, (c) protect the security or integrity of our products and services, (d) protect SpriggHR Inc., our clients or the public from harm or illegal activities, or (e) respond to an emergency which we believe in good faith requires us to disclose information to assist in preventing the death or serious bodily injury of any person.

Business Transfers: We may share or transfer information we collect under this privacy policy in connection with any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company. You will be notified via email and/or a prominent notice on the Products & Services if a transaction takes place, as well as any choices you may have regarding your information.

How we store and secure information we collect

Information storage and security

We use data hosting service providers and data centers in Canada to host the information we collect, and we use technical measures to secure your data. While we implement safeguards designed to protect your information, no security system is impenetrable and due to the inherent nature of the Internet, we cannot guarantee that data, during transmission through the Internet or while stored on our systems or otherwise in our care, is absolutely safe from intrusion by others.

By using our server and data center services, responsibility for securing storage and access to the information you put into the Products & Services rests with SpriggHR Inc. and server/data center providers.

How long we keep information

How long we keep information that we collect about you depends on the type of information, as described further below. After such time, we will either delete or make your information anonymous, if this is not possible (for example, because the information has been stored in backup archives), then we will securely store your information and isolate it from any further use until deletion is possible.

Account information: We retain your account information for as long as your account is active and a reasonable time thereafter for when your Administrator disables, disables & archives, or deletes your account. We also retain some of your information as necessary to comply with our legal obligations, to resolve disputes, to enforce our agreements, to support business operations, and to continue to develop and improve our Products & Services. Where we retain information for Product/Service improvement and development, we take steps to eliminate information that directly identifies you, and we only use the information to uncover collective insights about the use of our Products & Services, not to specifically analyze personal characteristics about you.

Information you share on the Products & Services: If your account is disabled or disabled & archived, the information and content that you have provided will remain in order to allow your Administrator to make full use of the Products & Services and meet their legal obligation with regards to data retention regulations. For example, we continue to display feedback messages you sent to other Users that received them and continue to display content you provided for Administrators such as goal and performance review data.

Managed accounts: If the Products & Services are made available to you through your employer or organization, we retain your information as long as required by the Administrator of your account.

Marketing information: If you have elected to receive marketing emails from us, we retain information about your marketing preferences for a reasonable period of time from the date you last expressed interest in our Products & Services, such as when you last opened an email from us or ceased your SpriggHR Inc. account. We retain information derived from cookies and other tracking technologies for a reasonable period of time from the date such information was created.

How to access and control your information

You have certain choices available to you when it comes to your information. Below is a summary of those choices, how to exercise them and any limitations.

Your Choices:

You have the right to request a copy of your information, to object to our use of your information (including for marketing purposes), to request the deletion or restriction of your information, or to request your information in a structured, electronic format. Below, we describe the tools and processes for making these requests. You can exercise some of the choices by logging into the Products & Services and using settings available within the Products & Services or your account. Where the Products & Services are administered for you by an Administrator (see “Notice to End Users” below), you may need to contact your Administrator to assist with your requests first. For all other requests, you may contact us as provided in the Contact Us section below to request assistance.

Your request and choices may be limited in certain cases: for example, if fulfilling your request would reveal information about another person, or if you ask to delete information which we or your Administrator are permitted by law or have compelling legitimate interests to keep. Where you have asked us to share data with third parties, for example, by installing third-party apps, you will need to contact those third-party service providers directly to have your information deleted or otherwise restricted. If you have unresolved concerns, you may have the right to complain to a data protection authority in the country where you live, where you work or where you feel your rights were infringed.

Access and update your information: Our Products & Services give you the ability to access and update certain information about you from within the Product/ Service. For example, you can access your profile information from your account and search for content containing information about you. You can update your profile information within your profile settings and modify content that contains information about you using the editing tools associated with certain customizable content.

Disable/ Disable & Archive your account: If you no longer wish to use our Products & Services, your Administrator may be able to disable/disable & archive your Products & Services account. If you are an Administrator and are unable to disable/disable & archive an account through your Administrator settings, please contact SpriggHR Inc. support. Please be aware that disabling/disabling & archiving your account does not delete your information; your information remains visible to other Product & Service Users based on your past participation within the Products & Services. For more information on how to delete your information, see below.

Delete your information: Our Products & Services give you the ability to delete certain information about you from within the Products & Services. For example, you can remove content that contains information about you using editing tools associated with that content, and you can remove certain profile information within your profile settings. Please note, however, that we may need to retain certain information for record keeping purposes, to complete transactions or to comply with our legal obligations.

Request that we stop using your information: In some cases, you may ask us to stop accessing, storing, using and otherwise processing your information where you believe we don’t have the appropriate rights to do so. For example, if you believe a Products & Services account was created for you without your permission or you are no longer an active user, you can request that we delete your account as provided in this policy. Where you gave us consent to use your information for a limited purpose, you can contact us to withdraw that consent, but this will not affect any processing that has already taken place at the time. You can also opt-out of our use of your information for marketing purposes by contacting us, as provided below. When you make such requests, we may need time to investigate and facilitate your request. If there is delay or dispute as to whether we have the right to continue using your information, we will restrict any further use of your information until the request is honoured or the dispute is resolved, provided your Administrator does not object (where applicable). If you object to information about you being shared with a third-party app, please disable the app or contact your Administrator to do so.

Opt out of communications: You may opt out of receiving promotional communications from us by using the unsubscribe link within each email or by contacting us as provided below to have your contact information removed from our promotional email list or registration database. Even after you opt out from receiving promotional messages from us, you will continue to receive transactional messages from us regarding our Products & Services. You can opt out of some notification messages in your account settings that are customized by your Administrator.

Data portability: Data portability is the ability to obtain some of your information in a format you can move from one service provider to another (for instance, when you transfer your data from one software system to another). Depending on the context, this applies to some of your information, but not to all of your information. Should you request it, we will provide you with an electronic file of your basic account information and the information you create on the spaces you under your sole control, like your User profile. Your Administrator can generate reports based on aggregate data and individual reports such as performance reviews, goals, compensation and time-off information.

How we transfer information we collect internationally

International transfers of information we collect

We collect information globally and primarily store that information in Canada. We transfer, process and store your information outside of your country of residence, to wherever our third-party service providers or we operate for the purpose of providing you the Products & Services. Wherever we transfer your information, we take steps to protect it.

International transfers within SpriggHR Inc. : To facilitate our global operations, we transfer information to Canada and allow access to that information from countries in which SpriggHR Inc. is owned or operated in for the purposes described within this policy. These countries may not have the equivalent privacy and data protection laws to the laws of the many countries where our clients and Users are based. When we share information about you within and among SpriggHR Inc., we make use of standard contractual data protection clauses. When we share information of clients in the European Economic Area, we make use of European Commission approved standard contractual data protection clauses, binding corporate rules for transfers to data processors, or other appropriate legal mechanisms to safeguard the transfer.

International transfers to third parties: Some of the third parties described in this privacy policy, which provide services to us under contract, are based in other countries that may not have equivalent privacy and data protection laws to the country in which you reside. When we share information of clients in the European Economic Area, we make use of European Commission approved standard contractual data protection clauses, binding corporate rules for transfers to data processors, or other appropriate legal mechanisms to safeguard the transfer.

Other important privacy information

Notice to End Users

Our Products & Services are intended for use by organizations. Where the Products & Services are made available to you through an organization such as your employer, that organization is the Administrator of the Products & Services and is responsible for the accounts and or Products & Services sites over which it has control. If this is the case, please direct your privacy questions to your Administrator as your use of the Products & Services may be subject to that organization’s policies. We are not responsible for the privacy or security practices of an Administrator’s organization, which may be different than this policy.

Administrators are able to:

  • Reset your username and/or password
  • Restrict, disable or terminate your access to the Products & Services and your account
  • Access information in and about your account
  • Access or retain information stored as part of your account
  • Authorize third-party apps or other APIs
  • Change the email address associated with your account
  • Change your information, including profile information
  • Restrict your ability to edit, modify or delete information

Our policy towards children

The Products & Services are not directed to individuals under the legal working age for various industries in Canada. We do not knowingly collect personal information from children under the legal working age. If we become aware that a child under the legal working age has provided us with personal information, we will take steps to delete such information. If you become aware that a child has provided us with personal information, please contact us.

Changes to our Privacy Policy

We may change this privacy policy from time to time. We will post any privacy policy changes on this page and, if the changes are significant, we will provide a more prominent notice by adding a notice on the Products & Services websites, Administrator communications, or by sending you an email notification. We will also keep prior versions of this Privacy Policy in an archive for your review. We encourage you to review our privacy policy whenever you use the Products & Services to stay informed about our information practices and the ways you can help protect your privacy.

If you disagree with any changes to this privacy policy, you will need to stop using the Products & Services and disable/disable & archive and/or delete your account(s), as outlined above.

Contact Us

Your information is controlled by SpriggHR Inc. If you have any questions or concerns about how your information is handled, please direct your inquiry to SpriggHR Inc. which is responsible for facilitating such inquiries.

SpriggHR Inc.
100 Broadview Avenue, Ste 300
Toronto, Canada, M4M 3H3
1-888-797-5583
Email: [email protected]